>> Microsoft Windows Multiple Kerberos Vulnerabilities (MS05-042)
Title : Microsoft Windows Multiple Kerberos Vulnerabilities (MS05-042) VUPEN ID : VUPEN/ADV-2005-1356 CVE ID : CVE-2005-1981 - CVE-2005-1982 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-08-09
Technical Description
Two vulnerabilities were identified in Microsoft Windows, which could be exploited by attackers to cause a denial of service, disclose sensitive information or conduct spoofing attacks.
The first issue is due to an error in the method used by domain controllers to process specially crafted Kerberos messages (port 88), which could be exploited by authenticated attackers to cause the service that is responsible for authenticating users in an Active Directory domain to stop responding.
The second flaw is due to an error in the implementation of the PKINIT protocol when validating received data, which could be exploited by local attackers to access sensitive information, spoof a domain controller, and view encrypted network communication.